Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-04-03 CVE-2016-10316 Open Redirect vulnerability in Jensenofscandinavia Al3G Firmware, Al5000Ac Firmware and Al59300 Firmware
Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev.
network
low complexity
jensenofscandinavia CWE-601
6.1
2017-04-03 CVE-2016-10315 Open Redirect vulnerability in Jensenofscandinavia Al3G Firmware, Al5000Ac Firmware and Al59300 Firmware
Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev.
network
low complexity
jensenofscandinavia CWE-601
6.1
2017-04-03 CVE-2016-10221 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Artifex Mupdf 1.10A
The count_entries function in pdf-layer.c in Artifex Software, Inc.
local
low complexity
artifex CWE-119
5.5
2017-04-03 CVE-2016-10220 NULL Pointer Dereference vulnerability in Artifex Ghostscript 9.20
The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc.
local
low complexity
artifex CWE-476
5.5
2017-04-03 CVE-2016-10219 Divide By Zero vulnerability in Artifex Ghostscript 9.20
The intersect function in base/gxfill.c in Artifex Software, Inc.
local
low complexity
artifex CWE-369
5.5
2017-04-03 CVE-2016-10218 NULL Pointer Dereference vulnerability in Artifex Ghostscript 9.20
The pdf14_pop_transparency_group function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc.
local
low complexity
artifex CWE-476
5.5
2017-04-03 CVE-2016-10217 Use After Free vulnerability in Artifex Ghostscript 9.20
The pdf14_open function in base/gdevp14.c in Artifex Software, Inc.
local
low complexity
artifex CWE-416
5.5
2017-04-03 CVE-2016-10209 NULL Pointer Dereference vulnerability in Libarchive 3.2.2
The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file.
local
low complexity
libarchive CWE-476
5.5
2017-04-02 CVE-2016-8802 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei products
The security policy processing module in Huawei Secospace USG6300 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6500 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6600 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200 allows authenticated attackers to setup a specific security policy into the devices, causing a buffer overflow and crashing the system.
network
low complexity
huawei CWE-119
6.5
2017-04-02 CVE-2016-8795 Integer Overflow or Wraparound vulnerability in Huawei products
Huawei CloudEngine 12800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 5800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 6800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 7800 with software V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 8800 with software V100R006C00; and Secospace USG6600 with software V500R001C00 allow remote unauthenticated attackers to craft specific IPFPM packets to trigger an integer overflow and cause the device to reset.
network
high complexity
huawei CWE-190
5.9